Repository navigation
fix(install): resolve every tool version at install time, and upgrade on re-run - #81
Merged
Merged
Conversation
… on re-run A version written into this repo is current on the day someone types it and stale every day after. Go was pinned to 1.26.7 while upstream was on 1.27.1, which is also why hyperi-ci had to bump golangci-lint -- a linter behind the toolchain cannot read the newer stdlib. The `--pinned` flag was never the thing biting: it defaults off, so a normal install already resolved latest for all twelve tools in `hyperi_versions`. What bound on every install was `go`, `rustup`, `fnm`, `openbao` and `flarectl`. Removed outright: - `hyperi_versions`, `hyperi_pinned`, `install.sh --pinned`, and `tools/check_version_pins.py` with its tests. Every task already carried an `else latest` branch, so deleting the map changed no default -- it removed the only path that installed something older. The drift check existed to keep a hand-copied mirror of hyperi-ci honest, and the mirror is what went. Resolved at install time instead: - go: `go.dev/dl/?mode=json` gives the current stable and a SHA256 per file, so the download stays verified. hyperi-update already used this endpoint. - rustup: the current `rustup-init` plus the `.sha256` published beside it. - fnm, openbao, flarectl: `/releases/latest`, or `@latest` for flarectl. Re-running a role now upgrades rather than skipping: - `cargo install-update --all --locked`, gated on `--list` reporting something outdated so a current box pays one registry poll instead of a rebuild sweep. - `rustup update stable`, gated on `rustup check`. - flarectl loses its `creates:` guard, since `go install` re-links regardless. Kept deliberately: `node_major` selects an LTS line rather than a release, and NodeSource's signed repo patches it in place. Rust needs no equivalent -- edition 2024 comes with whatever stable rustup installs. Also fixes a check-mode gap the live resolution exposed: unpacking Go had no `not ansible_check_mode` guard, which never showed while the pin matched what was already installed. run-tests.sh green, 42 tests. Full-repo ansible-lint goes 307 findings to 304.
…f failed `rustup check` and `cargo install-update --list` both carry failed_when: false, so a broken toolchain returned empty output and the update tasks skipped as if everything were current. Unmeasurable is not the same as up to date. Found on desktop-derek, where ~/.rustup is a dangling symlink to a /cache volume that was rebuilt without it, so every rustup call exits non-zero.
Contributor
|
Released in v2.24.13 -- https://github.com/hyperi-io/hyperi-developer/releases/tag/v2.24.13 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
A version written into this repo is current the day someone types it and stale every day after. Go was pinned at 1.26.7 while upstream was on 1.27.1 - which is also why hyperi-ci had to bump golangci-lint, since a linter behind the toolchain cannot read the newer stdlib.
Worth saying up front:
--pinnedwas never the thing biting. It defaults off, so a normal install already resolved latest for all twelve tools inhyperi_versions. The pins that bound on every install werego,rustup,fnm,openbaoandflarectl.Gone entirely:
hyperi_versions,hyperi_pinned,install.sh --pinned, andtools/check_version_pins.pywith its tests. Every task already had anelse latestbranch, so deleting the map changed no default - it removed the only path that installed something older. The drift check existed to keep a hand-copied mirror of hyperi-ci honest, and the mirror is what went. That check was also failing on every PR to this repo, including #77, for a bump nobody here made.Resolved at install time instead:
go.dev/dl/?mode=jsongives the current stable plus a SHA256 per file, so the download stays verified.hyperi-updatealready used this exact endpoint, so the role was the outlier, not the script.rustup-initand the.sha256published beside it./releases/latest, or@latestfor flarectl.Re-running a role now upgrades instead of skipping, which the
creates:guards used to prevent:cargo install-update --all --locked, gated on--listreporting something outdated so a current box pays one registry poll rather than a rebuild sweep. Rust already had the tooling for this - the role installs cargo-update and the comments called it the refresh path, it was just never wired in.rustup update stable, gated onrustup check.creates:guard, sincego installre-links regardless.Kept on purpose:
node_majorpicks an LTS line rather than a release, and NodeSource's signed repo patches it in place. Rust needs no equivalent - edition 2024 comes with whatever stable rustup installs.flarectlis the one place latest trades away a real guard: it sits on cloudflare-go's v0 branch, which makes no semver promise. Taken deliberately - it is a CLI, and a stale one is the worse failure.Two bugs surfaced on the way and are fixed here. Unpacking Go had no
not ansible_check_modeguard, invisible while the pin matched what was installed. And both new version checks carryfailed_when: false, so a broken toolchain returned empty output and the upgrade skipped as if current - unmeasurable is not the same as up to date, so a failed check now falls through to attempting the upgrade.Verified on desktop-derek, a real converge rather than check mode: Go went 1.26.0 to go1.27.1, and golangci-lint installed 2.13.2 - newer than even hyperi-ci's v2.13.1 pin.
run-tests.shgreen with 42 tests, and full-repoansible-lintdrops from 307 findings to 304 (measured against main in a worktree), so this adds none.